Overview
Pocket ID is a self-hosted identity provider that speaks OpenID Connect and OAuth 2.0 and is OpenID Connect Certified. Its defining choice is that users can only sign in with passkeys, including hardware keys such as a YubiKey, so there are no passwords to store, reset or leak. The project's stated goal is to be simple enough for cases where Keycloak or Ory Hydra would be overkill.
Setup is usually a single Docker container. You register each application as an OIDC client in the admin UI and point it at Pocket ID's discovery URL; apps that do not support OIDC can be put behind a separate proxy such as OAuth2 Proxy. User groups can be passed to apps in the token.
It is free under the BSD 2-Clause licence and maintained on GitHub with an active contributor base. It is aimed at homelabs and small teams rather than at customer-facing sign-up, and anyone who needs passwords, SAML or enterprise directory features should look at authentik, Keycloak or Kanidm.
Pricing and plans
checked 28 Sept 2026Free tier · no card
Completely free and open source (BSD 2-Clause); self-hosted with Docker, no paid tiers
| Plan | Price | What you get |
|---|---|---|
| Pocket ID | Free | BSD 2-Clause, self-hosted |
What it does
- Passkey-only login
- Users authenticate with passkeys or hardware security keys; no passwords.
- OIDC Certified
- Certified OpenID Connect and OAuth 2.0 provider usable by any OIDC client.
- Admin UI
- Web interface to manage users, groups and OIDC clients.
- Docker setup
- Recommended installation is a single Docker container.
- Groups in tokens
- Group membership can be sent to apps via the groups scope.
Strengths and limitations
Strengths
- Very quick to set up compared with Keycloak
- Phishing-resistant passkey login by design
- Free, permissively licensed and lightweight
- OpenID Connect Certified
Limitations
- Passkeys are the only sign-in method
- No built-in proxy for apps without OIDC support
- Self-hosted only, community support
- Not built for customer sign-up flows or multi-tenant B2B
Who it suits
Good for
- Homelabs securing self-hosted services
- Small teams wanting passwordless SSO
- Hardware-key users
Look elsewhere if
- Apps whose users need password or social login
- Enterprises needing SAML or LDAP
Alternatives to Pocket ID
| Tool | From | Free option | Stages |
|---|---|---|---|
| Amazon Cognito Cloud user directory and auth service | Usage-based | Free tier | |
| Appwrite Cloud Open-source backend-as-a-service (database, auth, storage, functions, hosting) | $25/mo | Free tier | |
| Asgardeo Hosted CIAM (with open-source self-hosted option) | $20/mo | Free tier | |
| Authelia Open-source SSO and 2FA portal for reverse proxies | — | Free tier | |
| Authgear Open-source CIAM (cloud, VPC or one-time self-host licence) | $50/mo | Free tier | |
| Better Auth Open-source TypeScript auth library | $20/mo | Free tier |
Questions
Is Pocket ID free?
Yes. It is open source under the BSD 2-Clause licence with no paid plans.
Does Pocket ID support passwords?
No. It only supports passkey authentication, by design.
How do I protect apps without OIDC using Pocket ID?
Use a separate proxy such as OAuth2 Proxy in front of the app, with Pocket ID as its OIDC provider.
Pocket ID vs Keycloak?
Pocket ID is far simpler and passkey-only; Keycloak supports many more protocols and login methods but is heavier to run.
Sources read for this page